ASUS Control Center Enterprise Hit by Critical Zero‑Day Granting Unauthenticated Root Privileges
ASUS has released an urgent security advisory after uncovering a high‑severity flaw in its Control Center Enterprise (ACC) software, catalogued as CVE‑2026‑75754. The vulnerability, which exists in version 4.0.0.2 and all prior releases, enables an attacker with no credentials to obtain root‑level access on systems managed by the platform.
The issue stems from inadequate authentication checks within the ACC service, allowing malicious actors to bypass normal login procedures and execute commands with full administrative privileges. Because ACC is typically deployed in corporate environments to oversee fleets of ASUS devices, the potential impact ranges from data exfiltration to the deployment of additional malware across an entire network.
ASUS’ bulletin advises organizations to treat the defect as critical and to apply the forthcoming patch immediately once it becomes available. In the interim, the company recommends disabling remote access features of ACC where feasible and monitoring logs for any unexpected activity that could indicate exploitation.
The flaw was initially reported by the security research collective GBHackers, who provided technical details that helped ASUS confirm the vulnerability’s scope. While the exact timeline of the discovery has not been disclosed, the rapid disclosure underscores the ongoing collaboration between independent researchers and vendors in addressing software weaknesses before they can be weaponized at scale.
Industry analysts note that the exposure highlights a broader challenge for enterprise‑grade management tools, which must balance ease of deployment with robust security controls. As organizations continue to adopt centralized device‑management solutions, the incident serves as a reminder to maintain rigorous patch‑management cycles and to conduct regular security assessments of critical infrastructure components.
Comments (0)
Be the first to comment.
Join the discussion